About this role
Job Type
Full-time
Description
Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a business organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.
Our organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.
Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.
Roles and Responsibilities:
Cybersecurity Engineer to design, and secure air-gapped Kubernetes/OpenShift platforms in classified enclaves. This role combines container platform expertise, federal compliance (NIST 800-53, DISA STIGs, RMF/ATO), CI/CD security automation, and incident response operations. Support architect disconnected container ecosystems, aid implementation of automated security controls, accelerate ATO timelines, and assess platforms supporting mixed sensitivity workloads in SCIFs.
Air-Gapped Container Platforms: Design and aid implementation of multi-tenant Kubernetes/OpenShift clusters in disconnected enclaves. Manage registry governance, image signing, SBOM/provenance, vulnerability gating, and offline patching. Implement admission control (OPA Gatekeeper, Kyverno) and RBAC for multi-tenancy in classified environments.
CI/CD Security Automation: Aid design/securing CI/CD pipelines integrating SAST, DAST, IaC scanning, and automated compliance checks. Generate RMF/ATO evidence via OSCAL mappings and eMASS integration. Enforce promotion gates requiring signed/provenanced artifacts and passing STIG checks.
Federal Compliance & RMF: Tailor NIST 800-53 controls for containerized systems using shared responsibility matrices. Apply Kubernetes/Docker/OpenShift DISA STIGs and track exceptions. Implement continuous monitoring (CONMON) dashboards via on-prem tools (Prometheus, Falco, auditd). Reduce ATO lead times through automation and evidence generation.
Zero Trust & Identity: Implement Zero Trust in Kubernetes using mTLS, service mesh (SPIFFE/SPIRE), and identity propagation across build/runtime layers. Manage offline PKI operations with short-lived certificates and air-gapped roots. Design east-west segmentation and cross-domain artifact transfer with tamper-evident controls.
Knowledge, Skills, and Abilities:
Knowledge:
Working knowledge of RMF, NIST standards, SA&A processes, DoD cybersecurity policies to include:
• Federal cybersecurity frameworks: NIST 800-53, DISA STIGs, CNSS/CNSSI policies, RMF/ATO workflows
• Container security standards and hardening baselines for Kubernetes, OpenShift, Docker
• OSCAL control mapping frameworks and eMASS integration
• Shared responsibility models in cloud-native and containerized environments
• Zero Trust architecture principles and implementation patterns
• Compliance automation and evidence generation best practices
• Multi-domain classification handling and cross-domain data movement
Skills:
• Strong interpersonal and communication skills to engage senior Government stakeholder
• Hands-on expertise with Kubernetes, OpenShift, RKE2 in air-gapped/classified environments
• Container registry management (image signing, SBOM generation, vulnerability scanning: Trivy, Grype, Syft, Cosign)
• CI/CD pipeline design and implementation (GitLab, Jenkins) for disconnected networks with artifact promotion
• Security testing automation: SAST, DAST, IAST, SCA, IaC scanning, and pipeline integration
• Kubernetes security hardening, admission control (OPA Gatekeeper, Kyverno), and RBAC design
Abilities:
• Lead or contribute to security initiatives requiring cross-functional coordination
• Manage competing priorities and complex stakeholder relationships
• Architect secure, scalable containerized platforms for mixed-sensitivity workloads in SCIFs
• Map CI/CD artifacts to RMF/ATO controls and accelerate authorization timelines through automation
• Tailor and reconcile federal compliance requirements across NIST, CNSS, and program-specific directives
• Implement and enforce Zero Trust principles end-to-end (build through runtime)
• Operate and troubleshoot Kubernetes clusters in air-gapped enclaves with minimal external support
• Detect, investigate, and respond to security incidents while maintaining data integrity in classified environments
• Coordinate between development, security, and operations teams to implement secure, compliant practices
• Design and execute disaster recovery and resilience strategies across isolated sites
Requirements
IAT/IAM III Required:
· Certified Information Security Manager (CISM)
or
· Certified Information Security Analyst (CISA)
or
· Certified Information Systems Security Professional (CISSP)
Certifications Preferred
· Certified Kubernetes Administrator (CKA)
· Certified Kubernetes Security Specialist (CKS)
· GIAC Security Essentials Certification (GSEC)
· Red Hat Certified Specialist in Kubernetes Administration (RHCSA/RHCE)
· Certified Application Security Engineer (CASE)
Education
Bachelor's degree in Cyber Security, Information Technology, or related field.
Security Requirement:
Hold a Top Secret Security Clearance with SCI eligibility.
Ability to Pass CI Poly.
Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.